Malware

Generic.MSIL.Bladabindi.ACF779FD (file analysis)

Malware Removal

The Generic.MSIL.Bladabindi.ACF779FD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.ACF779FD virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.ACF779FD?


File Info:

name: 0665C5A8DB15B960814F.mlw
path: /opt/CAPEv2/storage/binaries/e95a4ee36c72be8da3ed47f8ffe5a4b8b8c46c8a90fa0845bf925e17534d2ef8
crc32: C333A830
md5: 0665c5a8db15b960814f5e22e11502d5
sha1: 060b9e1dfb404a82afa99d66644da9fa339049de
sha256: e95a4ee36c72be8da3ed47f8ffe5a4b8b8c46c8a90fa0845bf925e17534d2ef8
sha512: 2d7dd3eb63b99084b89eccc1312adf919da761386edf12a654bfd2d4ac494871882a26a57ace0244ed5e7d58c91dcba9d4b70a28b8492dffe925eb02b11ef143
ssdeep: 6144:YKKLPKUUPof5W/q6w9eZGQn0slZKMcPVywOc9a13wtzjqYbVs6W:YcqRe8IZGKyrVyGS3Svq8Vq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18264E1383FE88119E2F507B4A06E05A145F1EB11B543D7EFE22466E9BB133D0DA0366B
sha3_384: b713f6d23de405c9645fd3d77790c0ea8381cb4492e5fb169604a8a43790cb32e7878870906a59bb5f7ef20641de990f
ep_bytes: ff2500004600302b00134f0000018685
timestamp: 2022-02-04 09:26:08

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.ACF779FD also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGeneric.MSIL.Bladabindi.ACF779FD
CylanceUnsafe
VIPREBackdoor.MSIL.Bladabindi.a (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
BitDefenderGeneric.MSIL.Bladabindi.ACF779FD
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.8db15b
CyrenW32/Trojan.BVX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.LX
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Packed.Generic-7672854-0
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanGeneric.MSIL.Bladabindi.ACF779FD
RisingBackdoor.Njrat!1.A096 (CLASSIC)
EmsisoftGeneric.MSIL.Bladabindi.ACF779FD (B)
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.0665c5a8db15b960
SophosML/PE-A + Mal/VMProtBad-A
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
MicrosoftBackdoor:MSIL/Bladabindi.BN
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.Agent.AXJ
AhnLab-V3Trojan/Win32.RL_Generic.C4336983
McAfeeTrojan-FIDH!0665C5A8DB15
MalwarebytesMalware.AI.2164676638
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.LX!tr
BitDefenderThetaGen:NN.ZemsilF.34182.tqW@aSxDdpf
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.ACF779FD?

Generic.MSIL.Bladabindi.ACF779FD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment